Roomza Hotel Intelligence
REMOTE · WWW.ROOMZA.COM · SCANNED SEP 21
The room-level truth layer of hospitality. Verified scores for exact hotel rooms, not just hotels.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability44
- 0% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Fail
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2277 tokens (~162/item across 14 items; 12 tools + 2 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 12 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 14 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
- Supports UI / widget rendering.Pass
How do I install the Roomza Hotel Intelligence MCP server?
Roomza Hotel Intelligence is a hosted endpoint at https://www.roomza.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · www.roomza.com
claude mcp add --transport http roomza-inc-roomza 'https://www.roomza.com/api/mcp'
{
"mcpServers": {
"roomza-inc-roomza": {
"url": "https://www.roomza.com/api/mcp"
}
}
} {
"servers": {
"roomza-inc-roomza": {
"type": "http",
"url": "https://www.roomza.com/api/mcp"
}
}
} [mcp_servers.roomza-inc-roomza] url = "https://www.roomza.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"roomza-inc-roomza": {
"type": "remote",
"url": "https://www.roomza.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add roomza-inc-roomza --url 'https://www.roomza.com/api/mcp' --transport streamable-http
mcp_servers:
roomza-inc-roomza:
url: "https://www.roomza.com/api/mcp" {
"McpServers": {
"roomza-inc-roomza": {
"Transport": "http",
"Url": "https://www.roomza.com/api/mcp"
}
}
} assistant mcp add roomza-inc-roomza -t streamable-http -u 'https://www.roomza.com/api/mcp'
{
"mcpServers": {
"roomza-inc-roomza": {
"type": "http",
"url": "https://www.roomza.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 16 Sept 26 0
- Stability: 0.97 → pass security
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- 9 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 6 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 4 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 3 Sept 26 0
- “ask_about_hotel” reworded the description of “hotel_id” cosmetic
- “get_hotel_pricing” reworded the description of “hotel_id” cosmetic
- “get_hotel_rooms” reworded the description of “hotel_id” cosmetic
- “get_nearby” reworded the description of “hotel_id” cosmetic
- “get_recent_reviews” reworded the description of “hotel_id” cosmetic
5 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Probed https://www.roomza.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=www.roomza.com | CN=YR1,O=Let's Encrypt,C=US | 19 Sept 2026 | 18 Dec 2026 | RSA 2048 | SHA256-RSA | 6d64a343fdb54daf259edff4f03619abac7 |
| SANs: www.roomza.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of www.roomza.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| roomza.com. | present | 55684 | 8 | Verified |
| www.roomza.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
| x-content-type-options | nosniff |
| referrer-policy | strict-origin-when-cross-origin |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://www.roomza.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://www.roomza.com/api/mcp | HTTPS enforced | 308 | https://www.roomza.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
add_special_request Add a special request ~74
Add a special request to one of your bookings (e.g. extra pillows, late checkout, anniversary celebration). Requires connecting your Roomza account.
| Name | Type | Req | Description |
|---|---|---|---|
| booking_id | string | yes | The booking ID to add the request to (get this from get_my_trips) |
| request | string | yes | The special request to add |
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | yes | – |
| ok | boolean | yes | – |
No examples provided.
ask_about_hotel Ask about a hotel ~108
Ask a specific question about a hotel that standard data may not answer. Uses AI with web search to find the answer. Examples: 'Does this hotel have Eiffel Tower views?', 'Is there a rooftop bar?', 'How far is it from the airport?'. Try get_hotel first; use this only when that data doesn't answer the question.
| Name | Type | Req | Description |
|---|---|---|---|
| hotel_id | string | yes | Hotel UUID (the URL slug also works) |
| question | string | yes | The specific question about the hotel |
| Name | Type | Req | Description |
|---|---|---|---|
| answer | string | yes | – |
No examples provided.
get_hotel Get hotel details ~113
Get full details for a hotel including: Roomza Truth summary, score breakdown, top strengths, hotel character (type, vibes, best-for), nearby landmarks with distances, neighborhood, awards, amenities, and review highlights from the open web. Use hotel name, slug, or UUID as the identifier. This is the FIRST call when the user names a specific hotel ('Wynn Las Vegas') — no search_hotels needed; the name resolves directly.
| Name | Type | Req | Description |
|---|---|---|---|
| identifier | string | yes | Hotel name, slug, or UUID |
| Name | Type | Req | Description |
|---|---|---|---|
| found | boolean | yes | – |
| hotel | – | yes | null when the hotel was not found |
No examples provided.
get_hotel_pricing Get room rates ~138
Get public room rates for a hotel (the hotel's own public rate; booking on Roomza never costs more). Pass check_in and check_out dates (YYYY-MM-DD) to get nightly from-prices per room type. Without dates, returns the hotel's typical nightly from-price. No booking links; to price and book an exact room, use secure_room.
| Name | Type | Req | Description |
|---|---|---|---|
| check_in | string | – | Check-in date in YYYY-MM-DD format (defaults to today) |
| check_out | string | – | Check-out date in YYYY-MM-DD format (defaults to tomorrow) |
| hotel_id | string | yes | Hotel UUID (the URL slug also works) |
| Name | Type | Req | Description |
|---|---|---|---|
| checkIn | – | yes | – |
| checkOut | – | yes | – |
| currency | string | yes | – |
| found | boolean | yes | false when the hotel is unknown |
| hotelName | – | yes | – |
| nights | – | yes | – |
| note | – | yes | – |
| roomTypes | array | yes | Per-room-type from-prices when dates were given and live rates exist |
| typicalNightlyFrom | – | yes | Hotel-level typical nightly from-price in dollars |
No examples provided.
get_hotel_rooms List hotel rooms ~83
List rooms for a hotel with individual Roomza scores, bed type, view, and floor. Pass room_number to look up a specific room.
| Name | Type | Req | Description |
|---|---|---|---|
| hotel_id | string | yes | Hotel UUID from search_hotels/get_hotel (the URL slug also works) |
| room_number | string | – | Look up a specific room by number, e.g. "434" |
| Name | Type | Req | Description |
|---|---|---|---|
| bookUrl | – | yes | Roomza booking link for this hotel; set only on the no-records fallback |
| count | integer | yes | – |
| note | – | yes | Copy encouraging a booking + review to start this hotel's room record |
| roomTypes | array | yes | Only populated when the hotel has no room records yet: bookable room types from live rates |
| rooms | array | yes | – |
No examples provided.
get_my_preferences Your preferences ~32
Get your saved room preferences, standing requests, and loyalty accounts on Roomza. Requires connecting your Roomza account.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| found | boolean | yes | – |
| loyaltyPrograms | array | yes | – |
| preferences | – | yes | – |
| standingRequests | array | yes | – |
| travelCards | array | yes | – |
No examples provided.
get_my_trips Your trips ~31
Look up your upcoming and past hotel bookings/trips on Roomza. Requires connecting your Roomza account.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | yes | – |
| past | array | yes | – |
| upcoming | array | yes | – |
No examples provided.
get_nearby Get nearby places and events ~107
Get nearby places (restaurants, bars, attractions, parks) and upcoming events near a hotel. Optionally filter events to a travel window with start_date / end_date.
| Name | Type | Req | Description |
|---|---|---|---|
| end_date | string | – | Travel end date YYYY-MM-DD -- filters events to this window |
| hotel_id | string | yes | Hotel UUID from search_hotels/get_hotel (the URL slug also works) |
| start_date | string | – | Travel start date YYYY-MM-DD -- filters events to this window |
| Name | Type | Req | Description |
|---|---|---|---|
| events | array | yes | – |
| found | boolean | yes | – |
| places | array | yes | – |
No examples provided.
get_recent_reviews Get guest reviews ~85
Get verified guest reviews for a hotel, including comments and insider tips. Pass room_number to get reviews for a specific room.
| Name | Type | Req | Description |
|---|---|---|---|
| hotel_id | string | yes | Hotel UUID (the URL slug also works) |
| limit | integer | – | Number of reviews (default 5) |
| room_number | string | – | Filter reviews to a specific room number, e.g. "434" |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | yes | – |
| note | – | yes | Set when no reviews are returned, e.g. unknown room |
| reviews | array | yes | – |
No examples provided.
search_hotels Search hotels ~216
DISCOVERY ONLY: search Roomza's hotel database by city, keyword, or natural language query when the user has NOT named a specific hotel. Understands hotel types (boutique, resort, luxury), vibes (romantic, trendy, quiet), traveler types (couples, families, solo), neighborhoods, and nearby landmarks. Example queries: 'boutique hotels in SoHo', 'romantic resort near the Eiffel Tower', 'pet-friendly hotel in Seattle'. Renders for the user as a full map with a multi-hotel list (so do not repeat the list in prose). NEVER use this when the user names one specific hotel (e.g. 'Wynn Las Vegas'): the map of many hotels is wrong for that. Call get_hotel with the hotel name instead, then get_hotel_rooms and show_rooms.
| Name | Type | Req | Description |
|---|---|---|---|
| city | string | – | Narrow results to a specific city |
| limit | integer | – | Max results (default 10) |
| query | string | yes | Hotel name, city, or keyword |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | yes | Number of hotels returned |
| hotels | array | yes | – |
| note | – | yes | Search note, e.g. a nearby-city fallback explanation |
No examples provided.
secure_room Price and lock a room ~109
Price and lock an exact room for specific dates with Room Lock. Returns the live price, cancellation policy, and a secure booking link with the room preselected. Requires connecting your Roomza account.
| Name | Type | Req | Description |
|---|---|---|---|
| check_in | string | yes | Check-in date, YYYY-MM-DD |
| check_out | string | yes | Check-out date, YYYY-MM-DD |
| guests | integer | – | Guest count (default 2) |
| room_id | string | yes | Room UUID (from show_rooms or get_hotel_rooms) |
| Name | Type | Req | Description |
|---|---|---|---|
| bookable | – | yes | true when a live bookable rate was found |
| bookingUrl | – | yes | Secure checkout link with the room preselected; payment happens only there |
| cancellation | – | yes | – |
| checkIn | – | yes | – |
| checkOut | – | yes | – |
| currency | string | yes | – |
| dueAtHotel | – | yes | Additional amount due at the hotel, dollars |
| guests | – | yes | – |
| hotelId | – | yes | – |
| hotelName | – | yes | – |
| indicativeOnly | – | yes | true when the price is from public listings, not bookable |
| message | – | yes | Set when ok is false |
| nights | – | yes | – |
| ok | boolean | yes | false = the request could not be quoted; see message |
| publicRate | – | yes | Hotel's public rate in dollars, for comparison |
| rateName | – | yes | – |
| roomId | – | yes | – |
| roomNumber | – | yes | – |
| totalToday | – | yes | Total charged today in dollars |
| trackRecord | – | yes | Hotel's room-request honor track record |
No examples provided.
show_rooms Show rooms ~275
REQUIRED whenever you present rooms. Whenever you are about to mention, recommend, or describe one or more specific rooms to the user, you MUST call this tool with those room UUIDs INSTEAD of writing the rooms in text. This is mandatory even when there is only ONE matching room — show it as a single hero card, never describe a lone room in prose. Call this BEFORE writing any prose about the rooms; the cards must appear first, then a brief summary. Pass room UUIDs (from get_hotel_rooms or search results) in ranked order, best first, 1 to 8 rooms. ALWAYS pass check_in and check_out when you know the user's dates: card prices are then for those exact dates. Without dates, cards show a typical from-price that can differ a lot from any specific dates. Each card shows photo, Roomza score, view, bed, and price. NEVER ask the user whether they want to see cards or images — just call this tool.
| Name | Type | Req | Description |
|---|---|---|---|
| check_in | string | – | Check-in date YYYY-MM-DD. Pass whenever the user's dates are known so card prices match those dates. |
| check_out | string | – | Check-out date YYYY-MM-DD. |
| room_ids | array | yes | Room UUIDs to display, in ranked order (best first). 1-8 rooms. |
| Name | Type | Req | Description |
|---|---|---|---|
| rooms | array | yes | – |
No examples provided.
What is the Roomza Hotel Intelligence MCP server?
Roomza Hotel Intelligence is an MCP server listed in the public MCP registry as io.github.roomza-inc/roomza. The room-level truth layer of hospitality. Verified scores for exact hotel rooms, not just hotels. This page covers its hosted endpoint (https://www.roomza.com/api/mcp).
Is the Roomza Hotel Intelligence MCP server safe to use?
Roomza Hotel Intelligence scores 83 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Roomza Hotel Intelligence MCP server expose?
Roomza Hotel Intelligence exposes 12 tools: search_hotels, get_hotel, get_hotel_rooms, get_recent_reviews, get_hotel_pricing, and 7 more. Their descriptions and schemas cost roughly 1,371 tokens of context every time the server is loaded.
Does the Roomza Hotel Intelligence MCP server require authentication?
No. We connected to Roomza Hotel Intelligence without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Roomza Hotel Intelligence MCP server still maintained?
Roomza Hotel Intelligence is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.